Effective Date: March 1, 2020
NeuroSoph Inc. Privacy Policy
Welcome to NeuroSoph Inc.
We are committed to protecting the privacy and security of all data we handle, including Protected Health Information (PHI) as defined under the Health Insurance Portability and Accountability Act (HIPAA). This Privacy Policy outlines how we collect, use, disclose, and protect information in compliance with HIPAA regulations and other applicable laws, while also adhering to best practices for related privacy concerns.
Scope of This Privacy Policy
This Privacy Policy applies to all data collected by NeuroSoph Inc. through our website, products, and services. It includes information shared by government entities, employees, contractors, and other authorized users of our systems.
NeuroSoph Inc. adheres to stringent privacy and security standards for handling PHI. Additionally, this Privacy Policy addresses data governance practices relevant to AI technologies.
Information We Collect
We collect information necessary for service delivery, operational efficiency, and compliance with legal obligations. This includes:
1. Personally Identifiable Information (PII)
- Name, email address, phone number, and other contact details provided during inquiries or correspondence.
- Employment-related information for authorized users accessing NeuroSoph Inc. systems.
2. Protected Health Information (PHI)
- PHI related to healthcare services provided by government entities, including:
- Information about physical or mental health conditions.
- Details about healthcare services received or planned.
- Payment information related to healthcare services.
3. Anonymized Data
- Aggregated data used for internal research and analytics purposes that cannot be traced back to individuals.
4. Cookies and Tracking Technologies
- Operational cookies used on our website to improve functionality and user experience.
How We Use Your Information
We use the information we collect for the following purposes:
- Service Delivery: To provide products and services requested by government entities in accordance with contractual agreements.
- Compliance: To ensure compliance with HIPAA regulations when handling PHI and other applicable laws governing data privacy and security.
- AI Data Governance: To analyze anonymized data for improving AI-driven solutions while maintaining strict confidentiality standards.
- Communication: To respond to inquiries, provide updates about our services, or notify users of changes to this Privacy Policy.
HIPAA Compliance
NeuroSoph Inc. is committed to maintaining the confidentiality, integrity, and availability of sensitive health-related data. While HIPAA does not issue official certifications, our operations follow all applicable HIPAA guidelines and best practices when delivering our solutions.
Privacy Rule
- We safeguard PHI by limiting its use or disclosure without explicit authorization except for purposes related to treatment, payment, or healthcare operations as defined by HIPAA.
- Individuals have rights under HIPAA to access their PHI, request corrections, and control its use.
- We provide tools to capture user consent and enforce configurable access permissions, ensuring that PHI is only accessed only with appropriate authorization.
Breach Notification Rule
- In the event of a breach involving unsecured PHI:
- Affected individuals will be notified within 60 days of discovery via email or written communication.
- The breach will be reported to the U.S. Department of Health and Human Services (HHS) as required by law.
- NeuroSoph Inc. will take immediate steps to mitigate risks associated with the breach.
Exclusions
- While NeuroSoph Inc. builds its platform and services in alignment with HIPAA requirements, we do not store PHI unless explicitly required and governed under a Business Associate Agreement (BAA). HIPAA compliance responsibility remains a shared obligation with our clients.
AI-Specific Privacy Practices
Privacy by Design Principles
- NeuroSoph Inc. integrates privacy considerations into all stages of AI development to proactively identify risks and implement safeguards that protect sensitive data.
Transparency in Data Usage
- We ensure clear communication about how AI models process anonymized data while avoiding any input of sensitive or proprietary information into AI tools.
Data Minimization
- Only essential data is used for AI model training or analytics purposes; PHI is excluded from such processes unless explicitly authorized under HIPAA guidelines.
Disclosure of Information
We may disclose information under specific circumstances:
- Legal Compliance: To comply with federal or state laws or respond to valid legal requests from government authorities.
- Healthcare Operations: To support healthcare operations as permitted under HIPAA regulations.
- AI Development: Anonymized data may be disclosed for internal research purposes while ensuring no risk of re-identification.
Any disclosure involving PHI will strictly adhere to HIPAA’s “minimum necessary” standard.
Data Security Measures
NeuroSoph Inc. takes a proactive approach to safeguarding all data we handle:
- Technical Safeguards: Encryption protocols (AES-256), secure firewalls, intrusion detection systems (IDS), and regular vulnerability assessments.
- Administrative Safeguards: Employee training programs on HIPAA compliance and AI-specific privacy risks.
- Physical Safeguards: Restricted access to facilities housing sensitive data through badge systems, surveillance monitoring, and secure storage areas.
Data Retention Policy
We retain personal data only as long as necessary for service delivery or compliance with legal obligations:
- PHI is retained in accordance with HIPAA requirements (e.g., six years for audit logs).
- PII is deleted or anonymized once it is no longer needed for operational purposes or legal compliance.
User Rights Under HIPAA
Individuals whose PHI is handled by NeuroSoph Inc. have specific rights under HIPAA:
- Access: Request copies of their PHI maintained in designated record sets.
- Correction: Request corrections to inaccurate or incomplete PHI.
- Restriction: Request restrictions on certain uses or disclosures of their PHI.
- Confidential Communications: Request communications through alternative means or locations if necessary for privacy protection.
- Accounting of Disclosures: Request an accounting of instances where their PHI was disclosed without authorization.
To exercise these rights or inquire further about your data privacy under HIPAA regulations, please use our contact form or contact us at info@neurosoph.com.
Cookies Policy
Our website uses cookies solely for operational purposes such as improving functionality and user experience:
- Cookies do not collect sensitive personal information such as PII or PHI.
- Users can manage cookie preferences through browser settings; however, disabling cookies may impact website functionality.
Updates to This Privacy Policy
We reserve the right to update this Privacy Policy at any time in compliance with HIPAA regulations and best practices for AI-related privacy concerns:
- Changes will be posted on this page with an updated effective date.
- Significant updates will be communicated directly via email or other appropriate channels.
For questions about this Privacy Policy or concerns about your personal data under HIPAA regulations or AI-related practices, please use our contact form or contact us at:
NeuroSoph Inc.
120 Water Street, Suite 213
North Andover, MA, 01845
By interacting with NeuroSoph Inc., you acknowledge that you have read and understood this Privacy Policy in its entirety while trusting us to protect your sensitive information responsibly in compliance with both HIPAA standards and modern AI best practices.